10063593

Propagating Fraud Awareness to Hosted Applications

PublishedAugust 28, 2018
Assigneenot available in USPTO data we have
Technical Abstract

Patent Claims
9 claims

Legal claims defining the scope of protection, as filed with the USPTO.

1

1. A method comprising: receiving, by a gateway enforcement point, through a communication network from a client device used by a user, a first request to access a protected resource; responsive to receipt of the first request, authenticating, by the gateway enforcement point, the client device to establish a first authenticated communication session between the gateway enforcement point and the client device, with authenticating the client device including receiving, by the gateway enforcement point, authentication data relating to the user; further responsive to receipt of the first request to access the protected resource, sending, by the gateway enforcement point to a first cloud fraud detection system, a second request for fraud information relating to the user, with the second request including: (i) the authentication data, and (ii) a session identifier identifying the first authenticated communication session; receiving, by the gateway enforcement point from the first cloud fraud detection system, a first fraud data set indicative of fraud related information relating to the user; caching, in the gateway enforcement point as part of the first authenticated communication session, the first fraud data set; further responsive to receipt of the first request to access the protected resource, sending, by the gateway enforcement point to a second cloud fraud detection system, a third request for fraud information relating to the user, with the third request including: (i) the authentication data, and (ii) the session identifier; receiving, by the gateway enforcement point from the second cloud fraud detection system, a second fraud data set indicative of fraud related information relating to the user; caching, in the gateway enforcement point as part of the first authenticated communication session, the second fraud data set; and controlling, by the gateway enforcement point, access to the protected resource by the client device in a manner based upon both of the following: (i) the fraud related information of the first fraud data set, and (ii) the fraud related information of the second fraud data set.

2

2. The method of claim 1 wherein controlling access includes denying, by the gateway enforcement point, access to the client device of the protected resource based on at least one of the following: (i) the fraud related information of the first fraud data set, and (ii) the fraud related information of the second fraud data set.

3

3. The method of claim 1 wherein controlling access includes propagating, by the gateway enforcement point to a resource server hosting the protected resource: (i) the fraud related information of the first fraud data set, and (ii) the fraud related information of the second fraud data set.

4

4. A computer program product comprising: a machine readable storage device; and computer code stored on the machine readable storage device, with the computer code including instructions for causing a processor(s) set to perform operations including the following: receiving, by a gateway enforcement point, through a communication network from a client device used by a user, a first request to access a protected resource, responsive to receipt of the first request, authenticating, by the gateway enforcement point, the client device to establish a first authenticated communication session between the gateway enforcement point and the client device, with authenticating the client device including receiving, by the gateway enforcement point, authentication data relating to the user, further responsive to receipt of the first request to access the protected resource, sending, by the gateway enforcement point to a first cloud fraud detection system, a second request for fraud information relating to the user, with the second request including: (i) the authentication data, and (ii) a session identifier identifying the first authenticated communication session, receiving, by the gateway enforcement point from the first cloud fraud detection system, a first fraud data set indicative of fraud related information relating to the user, caching, in the gateway enforcement point as part of the first authenticated communication session, the first fraud data set, further responsive to receipt of the first request to access the protected resource, sending, by the gateway enforcement point to a second cloud fraud detection system, a third request for fraud information relating to the user, with the third request including: (i) the authentication data, and (ii) the session identifier, receiving, by the gateway enforcement point from the second cloud fraud detection system, a second fraud data set indicative of fraud related information relating to the user, caching, in the gateway enforcement point as part of the first authenticated communication session, the second fraud data set, and controlling, by the gateway enforcement point, access to the protected resource by the client device in a manner based upon both of the following: (i) the fraud related information of the first fraud data set, and (ii) the fraud related information of the second fraud data set.

5

5. The computer program product of claim 4 wherein controlling access includes denying, by the gateway enforcement point, access to the client device of the protected resource based on at least one of the following: (i) the fraud related information of the first fraud data set, and (ii) the fraud related information of the second fraud data set.

6

6. The computer program product of claim 4 wherein controlling access includes propagating, by the gateway enforcement point to a resource server hosting the protected resource: (i) the fraud related information of the first fraud data, and (ii) the fraud related information of the second fraud data set.

7

7. A computer system comprising: a processor(s) set; a machine readable storage device; and computer code stored on the machine readable storage device, with the computer code including instructions for causing the processor(s) set to perform operations including the following: receiving, by a gateway enforcement point, through a communication network from a client device used by a user, a first request to access a protected resource, responsive to receipt of the first request, authenticating, by the gateway enforcement point, the client device to establish a first authenticated communication session between the gateway enforcement point and the client device, with the authenticating the client device including receiving, by the gateway enforcement point, authentication data relating to the user, further responsive to receipt of the first request to access the protected resource, sending, by the gateway enforcement point to a first cloud fraud detection system, a second request for fraud information relating to the user, with the second request including: (i) the authentication data, and (ii) a session identifier identifying the first authenticated communication session, receiving, by the gateway enforcement point from the first cloud fraud detection system, a first fraud data set indicative of fraud related information relating to the user, caching, in the gateway enforcement point as part of the first authenticated communication session, the first fraud data set, further responsive to receipt of the first request to access the protected resource, sending, by the gateway enforcement point to a second cloud fraud detection system, a third request for fraud information relating to the user, with the third request including: (i) the authentication data, and (ii) the session identifier, receiving, by the gateway enforcement point from the second cloud fraud detection system, a second fraud data set indicative of fraud related information relating to the user, caching, in the gateway enforcement point as part of the first authenticated communication session, the second fraud data set, and controlling, by the gateway enforcement point, access to the protected resource by the client device in a manner based upon both of the following: (i) the fraud related information of the first fraud data set, and (ii) the fraud related information of the second fraud data set.

8

8. The computer system of claim 7 wherein controlling access includes denying, by the gateway enforcement point, access to the client device of the protected resource based on at least one of the following: (i) the fraud related information of the first fraud data set, and (ii) the fraud related information of the second fraud data set.

9

9. The computer system of claim 7 wherein controlling access includes propagating, by the gateway enforcement point and to a resource server hosting the protected resource: (i) the fraud related information of the first fraud data set, and (ii) the fraud related information of the second fraud data set.

Patent Metadata

Filing Date

Unknown

Publication Date

August 28, 2018

Inventors

Scott M. Andrews
Timothy J. Ashton
Leigh Doddy
Christopher J. Hockings
Trevor S. Norvill

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “PROPAGATING FRAUD AWARENESS TO HOSTED APPLICATIONS” (10063593). https://patentable.app/patents/10063593

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.